Tracked by #590. Depends on #593. Runtime-enforced outcomes also depend on #594.
Outcome
Registry Stack publishes a versioned, reviewable DPI Safeguards-aligned profile that maps relevant framework requirements to concrete Registry Stack controls, external operator responsibilities, or explicit unsupported gaps without inventing a dpi: field taxonomy or claiming blanket compliance.
Requirements
- Pin the exact DPI Safeguards framework source, version, retrieval provenance, and content digest used by the profile.
- Separate framework safeguards from semantic concepts and privacy classification vocabularies.
- Map only requirements relevant to Registry Stack's bounded responsibilities.
- For each mapping, record the safeguard reference, interpretation, applicable product surface, expected evidence, owner, and one status:
enforceable
declared_external
unsupported
not_applicable with rationale
- Bind
enforceable entries to stable safeguard-profile rule IDs and concrete implementation tests or runtime evidence.
- Keep organizational controls, legal determinations, retention operations, human oversight, and other external responsibilities visibly outside runtime enforcement when Registry Stack cannot prove them.
- Produce a deterministic coverage report from the selected Registry Stack release, enabled features, semantic/classification profiles, and safeguard profile.
- Prevent report-only configuration, descriptive metadata, or an unverified classification from being presented as enforced.
- Include a review and update procedure for new framework versions and changed Registry Stack capabilities.
Acceptance criteria
Non-goals
- A universal compliance engine
- Automated legal-basis or jurisdiction decisions
- Runtime interpretation of mutable framework web pages
- Replacing institution-specific risk assessment, approvals, or operating procedures
- Making every DPI Safeguards principle a Relay runtime feature
Tracked by #590. Depends on #593. Runtime-enforced outcomes also depend on #594.
Outcome
Registry Stack publishes a versioned, reviewable DPI Safeguards-aligned profile that maps relevant framework requirements to concrete Registry Stack controls, external operator responsibilities, or explicit unsupported gaps without inventing a
dpi:field taxonomy or claiming blanket compliance.Requirements
enforceabledeclared_externalunsupportednot_applicablewith rationaleenforceableentries to stable safeguard-profile rule IDs and concrete implementation tests or runtime evidence.Acceptance criteria
enforceableclaim points to a stable rule ID, enforcement point, and passing evidence.DPI Safeguards,HIPAA,GDPR, or another regime name as an inherent field classification.Non-goals